Bitnami package
mariadb
pkg:bitnami/mariadb
Vulnerabilities (116)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2023-52968 | Med | 4.9 | >= 10.4.0, < 10.4.33 | 10.4.33 | Mar 8, 2025 | MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table cr | |
| CVE-2025-21490 | Med | 4.9 | < 10.5.28 | 10.5.28 | Jan 21, 2025 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto | |
| CVE-2024-27766 | Med | 5.7 | >= 11.1.0, < 11.1.5 | 11.1.5 | Oct 17, 2024 | An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| CVE-2023-39593 | Med | 5.6 | >= 10.5.0, <= 10.5.0 | — | Oct 17, 2024 | Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| CVE-2023-26785 | Cri | 9.8 | >= 10.5.0, <= 10.5.0 | — | Oct 17, 2024 | MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed. | |
| CVE-2024-21096 | Med | 4.9 | < 10.5.25 | 10.5.25 | Apr 16, 2024 | Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MyS | |
| CVE-2023-22084 | Med | 4.9 | < 10.4.32 | 10.4.32 | Oct 17, 2023 | Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c | |
| CVE-2023-5157 | Hig | 7.5 | < 10.3.36 | 10.3.36 | Sep 27, 2023 | A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service. | |
| CVE-2022-47015 | Med | 6.5 | >= 10.3.0, < 10.3.39 | 10.3.39 | Jan 20, 2023 | MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer. | |
| CVE-2022-21595 | Med | 4.4 | < 10.2.42 | 10.2.42 | Oct 18, 2022 | Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromis | |
| CVE-2022-38791 | Med | 5.5 | >= 10.3.0, < 10.3.36 | 10.3.36 | Aug 27, 2022 | In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock. | |
| CVE-2022-32091 | Hig | 7.5 | >= 10.3.0, < 10.3.36 | 10.3.36 | Jul 1, 2022 | MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc. | |
| CVE-2022-32089 | Hig | 7.5 | >= 10.4.0, < 10.4.26 | 10.4.26 | Jul 1, 2022 | MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level. | |
| CVE-2022-32088 | Hig | 7.5 | >= 10.2.0, < 10.2.44 | 10.2.44 | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort. | |
| CVE-2022-32087 | Hig | 7.5 | >= 10.3.0, < 10.3.35 | 10.3.35 | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args. | |
| CVE-2022-32086 | Hig | 7.5 | >= 10.4.0, < 10.4.25 | 10.4.25 | Jul 1, 2022 | MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field. | |
| CVE-2022-32085 | Hig | 7.5 | >= 10.2.0, < 10.2.44 | 10.2.44 | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor. | |
| CVE-2022-32084 | Hig | 7.5 | >= 10.3.0, < 10.3.36 | 10.3.36 | Jul 1, 2022 | MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select. | |
| CVE-2022-32083 | Hig | 7.5 | >= 10.2.0, < 10.2.44 | 10.2.44 | Jul 1, 2022 | MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker. | |
| CVE-2022-32082 | Hig | 7.5 | >= 10.5.0, < 10.5.17 | 10.5.17 | Jul 1, 2022 | MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc. |
- affected >= 10.4.0, < 10.4.33fixed 10.4.33
MariaDB Server 10.4 before 10.4.33, 10.5 before 10.5.24, 10.6 before 10.6.17, 10.7 through 10.11 before 10.11.7, 11.0 before 11.0.5, and 11.1 before 11.1.4 calls fix_fields_if_needed under mysql_derived_prepare when derived is not yet prepared, leading to a find_field_in_table cr
- affected < 10.5.28fixed 10.5.28
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple proto
- affected >= 11.1.0, < 11.1.5fixed 11.1.5
An issue in MariaDB v.11.1 allows a remote attacker to execute arbitrary code via the lib_mysqludf_sys.so function. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- affected >= 10.5.0, <= 10.5.0
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- affected >= 10.5.0, <= 10.5.0
MariaDB v10.5 was discovered to contain a remote code execution (RCE) vulnerability via UDF Code in a Shared Object File, followed by a "create function" statement. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- affected < 10.5.25fixed 10.5.25
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MyS
- affected < 10.4.32fixed 10.4.32
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.43 and prior, 8.0.34 and prior and 8.1.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to c
- affected < 10.3.36fixed 10.3.36
A vulnerability was found in MariaDB. An OpenVAS port scan on ports 3306 and 4567 allows a malicious remote client to cause a denial of service.
- affected >= 10.3.0, < 10.3.39fixed 10.3.39
MariaDB Server before 10.3.34 thru 10.9.3 is vulnerable to Denial of Service. It is possible for function spider_db_mbase::print_warnings to dereference a null pointer.
- affected < 10.2.42fixed 10.2.42
Vulnerability in the MySQL Server product of Oracle MySQL (component: C API). Supported versions that are affected are 5.7.36 and prior and 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromis
- affected >= 10.3.0, < 10.3.36fixed 10.3.36
In MariaDB before 10.9.2, compress_write in extra/mariabackup/ds_compress.cc does not release data_mutex upon a stream write failure, which allows local users to trigger a deadlock.
- affected >= 10.3.0, < 10.3.36fixed 10.3.36
MariaDB v10.7 was discovered to contain an use-after-poison in in __interceptor_memset at /libsanitizer/sanitizer_common/sanitizer_common_interceptors.inc.
- affected >= 10.4.0, < 10.4.26fixed 10.4.26
MariaDB v10.5 to v10.7 was discovered to contain a segmentation fault via the component st_select_lex_unit::exclude_level.
- affected >= 10.2.0, < 10.2.44fixed 10.2.44
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Exec_time_tracker::get_loops/Filesort_tracker::report_use/filesort.
- affected >= 10.3.0, < 10.3.35fixed 10.3.35
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_args::walk_args.
- affected >= 10.4.0, < 10.4.25fixed 10.4.25
MariaDB v10.4 to v10.8 was discovered to contain a segmentation fault via the component Item_field::fix_outer_field.
- affected >= 10.2.0, < 10.2.44fixed 10.2.44
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component Item_func_in::cleanup/Item::cleanup_processor.
- affected >= 10.3.0, < 10.3.36fixed 10.3.36
MariaDB v10.2 to v10.7 was discovered to contain a segmentation fault via the component sub_select.
- affected >= 10.2.0, < 10.2.44fixed 10.2.44
MariaDB v10.2 to v10.6.1 was discovered to contain a segmentation fault via the component Item_subselect::init_expr_cache_tracker.
- affected >= 10.5.0, < 10.5.17fixed 10.5.17
MariaDB v10.5 to v10.7 was discovered to contain an assertion failure at table->get_ref_count() == 0 in dict0dict.cc.
Page 2 of 6